This page is the reference material behind those three sentences: the public signing key, what the signature does and doesn't cover, how the governance model enforces access, and what the infrastructure runs on.
Paste a synthesis ID, a link containing ?synthesis_id=, or raw JSON with a _stratalize block — verified in the browser with no Stratalize API for pasted JSON.
Assessment methodology: Stratalize AGM v1.0 →
Every receipt is signed with ML-DSA-65 under FIPS 204. Verification runs against the key below, published here and nowhere else. Anyone can check a receipt offline with no account and no request to Stratalize.
A signature is only worth what it covers. Both lists below are part of the specification.
ML-DSA-65 under FIPS 204 on every output, not as an upgrade path. Records created today are read in audits and claims years out.
Source data is released at the end of a session, with hashes and signed records persisting. Beyond that you set the window, from signed artifacts only to a full forensic chain. Where a workspace needs history to function, that content persists under your retention setting.
Pasted JSON verifies in the browser against the published key. No account, no API call.
Every receipt references the one before it, which is what makes the record worth entering into evidence.